First published: Mon Apr 20 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | ||
Drupal Cck Comment Reference | =6.x | |
Drupal Cck Comment Reference | =6.x-1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1342 is classified as a cross-site scripting (XSS) vulnerability which can potentially allow attackers to inject malicious scripts.
To resolve CVE-2009-1342, upgrade the CCK Comment Reference module to version 6.x-1.2 or later.
CVE-2009-1342 affects the CCK Comment Reference module version 6.x before 6.x-1.2.
Yes, CVE-2009-1342 can be exploited remotely by attackers through crafted comment titles.
The impact of CVE-2009-1342 includes the potential for attackers to execute arbitrary web scripts in the context of affected users.